 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
: j! D- w+ ? N% y& E8 A4 Q( JScan saved at 16:55:24, on 2006-5-60 Q! M/ y3 L. c8 V
Platform: Windows XP SP2 (WinNT 5.01.2600)) V( ?. X' p7 Z: ?$ u: b# l) I$ t
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)" D& O' {8 G: O! v! `
7 I3 N$ Z& f4 `" k2 X: C9 V
Running processes:, X7 Z/ q: f6 Z" A7 }0 c
C:\WINDOWS\System32\smss.exe
5 n4 M+ |4 U# E: ]* NC:\WINDOWS\system32\winlogon.exe# |. S0 E* |$ M9 _2 C! A Y
C:\WINDOWS\system32\services.exe
% m* O, h: {* ?+ F' W1 RC:\WINDOWS\system32\lsass.exe: O! _) Y9 O0 w1 u9 w
C:\Program Files\Common Files\Virtual Token\vtserver.exe- {+ o+ X" [5 g
C:\WINDOWS\system32\ibmpmsvc.exe, R# u3 X$ s7 g/ c
C:\WINDOWS\system32\svchost.exe
/ W8 Q! ^* s# [& x- q7 O) U. B4 zC:\WINDOWS\System32\svchost.exe
. x& M' \ ~& {, PC:\Program Files\Intel\Wireless\Bin\EvtEng.exe
7 b2 ]7 J5 x+ i( X$ P EC:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
" F5 P, Z% O6 p0 F" PC:\WINDOWS\system32\spoolsv.exe
3 u% X* \" d& S( o7 Q& ^# W3 p1 nC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE' [; Q; L- I5 X, d: ~) j( P5 o- q
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe. |- ^7 A" L# @* |6 |( h
C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe6 V* g' ~+ X3 Y
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE. O8 e+ O( u% y# [
C:\Program Files\F-Secure\Common\FSMA32.EXE
( y% T9 B6 e6 ?3 F* [' o4 Z& iC:\Program Files\F-Secure\Common\FSMB32.EXE
* N1 d3 N2 [0 v4 ~C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
8 V! m5 F+ z e. bC:\Program Files\F-Secure\Anti-Virus\fssm32.exe: p) \6 g9 A4 j3 }9 m4 V
C:\WINDOWS\System32\QCONSVC.EXE9 G( a/ ^5 d( ]% A+ E) Y; S
C:\Program Files\F-Secure\Common\FCH32.EXE
6 ~/ S+ q( X/ F: W/ E. z8 p2 rC:\Program Files\Intel\Wireless\Bin\RegSrvc.exe0 _8 Z# G! C; f4 ~
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe% W* N6 L, j4 F9 z5 D' C5 A" S) q! {
C:\WINDOWS\System32\TPHDEXLG.EXE
. o- E" p) b5 hC:\Program Files\F-Secure\Common\FAMEH32.EXE2 A! {4 R C- c, J' ~+ a9 |
C:\WINDOWS\system32\TpKmpSVC.exe
( \5 k* a1 t1 a: kC:\Program Files\F-Secure\Anti-Virus\fsqh.exe5 i" n3 n3 _$ I! M: T8 K
C:\Program Files\F-Secure\Anti-Virus\fsrw.exe. A# h' L, L/ r( r
C:\Program Files\F-Secure\Common\FNRB32.EXE
8 a c5 V$ E. K6 P, N" bC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
G3 n7 D3 ]% T5 @9 a& b' uC:\Program Files\F-Secure\Common\FIH32.EXE1 }( p b+ ~! x$ l6 }, C7 s; U( N
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
7 W: x" r% H1 X0 E/ r8 \C:\WINDOWS\Explorer.EXE& }9 r9 p% I1 |4 Q
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe% v9 l: x/ { ~( e! q: n
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
. y6 z" W7 ~; K- F) Y% D: lC:\WINDOWS\system32\hkcmd.exe9 S, S! h1 }6 w9 t4 a9 Y7 p+ a
C:\WINDOWS\system32\TpShocks.exe+ n2 U/ {( `8 @7 X9 q
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe6 v0 c! r v! C; Z9 @$ V
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe* G4 S" i# G! M, y* Q+ g* ~
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
9 F; \+ B; l4 ?* e( d7 \$ q' t" E# `C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe( a; S. m/ A, A5 j, n% O' T
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe# E+ D+ I" B7 ?( S7 Z& J
C:\WINDOWS\system32\dla\tfswctrl.exe
; i/ v. Z9 M; B+ ^1 X$ _C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
J$ K$ f2 s1 P, \/ m' Z0 N9 D qC:\IBMTOOLS\UTILS\ibmprc.exe
" g6 L6 z, e5 `( B! V+ c$ q8 S. [' HC:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE/ m% E, ^6 h' k' b3 w7 ~+ D
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
$ K5 n4 A' t+ u$ t1 oC:\WINDOWS\System32\svchost.exe* x3 [! W/ v- v+ q$ J: Z) a2 X
C:\WINDOWS\system32\rundll32.exe1 i8 m5 p. w' x( q& n
C:\Program Files\F-Secure\Common\FSM32.EXE
: F1 d5 \$ O% a+ [C:\WINDOWS\system32\CTFMON.EXE
. M2 @2 j8 `2 u, RC:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe! ?" T; V5 ^ V0 \0 V2 Y/ I
C:\Program Files\Digital Line Detect\DLG.exe
7 B( [- D' t6 {$ N7 ], t9 f9 LC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
$ k- f! G, f' M0 J7 zC:\Program Files\F-Secure\FSGUI\fsguidll.exe
# ~: z) z% z8 m$ x/ r: vC:\Program Files\Messenger\msmsgs.exe
^2 L' p5 q1 L* `1 h' ^" EC:\Program Files\Internet Explorer\iexplore.exe
# X6 ]6 Z3 p B$ [6 @+ ^C:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe' W# Z9 d) e4 ^4 z, k
9 \1 L) v! p+ s0 h! |; L+ U
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
; Y8 T6 l t4 d# r! e. KO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe4 i( {- H: ~# K' I% I
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe8 l0 ~4 F$ H$ v7 \, L( Z0 ?+ l
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe `- q3 u# e! I$ x {! B
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
K' R, m% ^6 L7 pO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper6 V- ~' d7 }3 ^- P
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
* ?! n u) Y1 d" `/ o' F* dO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
a3 T# l* O5 V+ \O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup( X4 x! ^2 o5 K% k" C1 |) b
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe, Z) q. e" q1 p1 w$ }4 x
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe; B" y# w7 a( |7 a% V
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe/ Y( W# C4 M+ W' w# B' p6 z3 X
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
@' ?' R0 U$ T5 LO4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r0 ] e4 G$ y: G, V/ k5 y; d, U
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
& C. w$ y/ h" P+ bO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe# x+ `/ |: J; a& `5 d. R% w1 d* O
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
0 y3 K0 H. @$ w! p& N, ZO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE/ m2 V3 \7 j- o- j& s
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
- n& g$ W+ N. } B% h5 v: g' |( XO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
. S8 Q! t* [0 {7 LO4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog8 z7 \# @6 V- R2 o0 \+ C
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration329 ]7 w; m5 ~% O2 o; k
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
7 A! Z( |( W% w' |O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
, @( v3 Z2 c+ W6 E4 jO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
5 h& n) |$ z3 U" s5 x4 VO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName u5 W/ R( ~7 [
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash, f+ i7 H2 y% _! A
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
7 }4 Q+ O. g* Y6 ^6 TO4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
{- v, x# Q6 D7 r3 vO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
' ?* L: R# z7 ~# t4 B# \7 mO4 - Global Startup: Digital Line Detect.lnk = ?
+ z1 W. G: L# o( g+ Z7 s3 tO4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe4 X: q$ v- U/ v" t: }' Y# \
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
3 [, n) o/ H1 [( w0 |9 O3 y% ~1 N- FO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
# d% ^0 n5 `3 _- i0 n* U0 Q! RO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll* l* U; ?9 ^- k8 ?3 V
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
. f# P; {! j3 V8 r( hO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
5 ^ G4 l. [. z/ l+ t6 [O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe5 g+ `% z. g( R$ I( ^. W
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe7 w' i. j' L8 j* b" z
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
1 t3 y6 l7 S' @+ R; \/ QO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
6 T* e9 l/ L4 X( y* r- bO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll0 M% e& O$ S0 g
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
4 S5 ? ^; p: ~ gO11 - Options group: [JAVA_IBM] Java (IBM)9 E8 F; d1 _- f- l( I; x
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
X0 S& w- ^3 F" A( _O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll$ x1 e6 k! S! v1 r5 _
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
7 ?+ s* o4 F4 R vO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll* G H6 ~ V7 G" p2 T6 K
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE! c, W2 y o. V! q! y/ x
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe) c' `) B0 R* d
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
+ l0 a" C- u! C1 o: |0 f) kO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
; m* H7 h/ f# ZO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe2 A0 k; X2 [# o% `3 v2 G& c
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
8 b0 L, N' B# `' C# UO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
. T" A! L( L" u: OO23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
; P- F8 V- w' L; H8 VO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe4 U) [( S l( |- D
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
+ P% E+ _- q/ p( F" ^$ uO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
3 v9 Y# t5 p- IO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
4 I" G. E2 m. S6 v% i7 v$ ^O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
! H7 w0 x0 K iO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
- A+ T, ~; L( U2 p8 l2 t wO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
( p4 x) @) o: t& u [. a, YO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
9 f+ L) W5 c5 z) zO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe. h0 N1 w9 N5 A
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|